Use Case: Physical Security

August 30, 2023 · View on GitHub

Use Case: Physical Security

Vendor: AMAG

ProductEvent TypesMITRE ATT&CK® TTPContent
Symmetry Access Control
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: AccessIT

ProductEvent TypesMITRE ATT&CK® TTPContent
Universal.NET
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: Avaya

ProductEvent TypesMITRE ATT&CK® TTPContent
Avaya VPN
  • failed-vpn-login
  • vpn-login
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Badge

ProductEvent TypesMITRE ATT&CK® TTPContent
Badge
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Badgepoint

ProductEvent TypesMITRE ATT&CK® TTPContent
Badgepoint
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Barracuda

ProductEvent TypesMITRE ATT&CK® TTPContent
Barracuda Firewall
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • remote-logon
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Brivo

ProductEvent TypesMITRE ATT&CK® TTPContent
Brivo
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: CatoNetworks

ProductEvent TypesMITRE ATT&CK® TTPContent
Cato Cloud
  • network-alert
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Check Point

ProductEvent TypesMITRE ATT&CK® TTPContent
Identity Awareness
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
NGFW
  • app-login
  • authentication-failed
  • authentication-successful
  • dlp-email-alert-in
  • dlp-email-alert-out
  • failed-vpn-login
  • local-logon
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Security Gateway
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Security Gateway Virtual Edition (vSEC)
  • authentication-failed
  • authentication-successful
  • vpn-login
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Cisco

ProductEvent TypesMITRE ATT&CK® TTPContent
Adaptive Security Appliance
  • authentication-failed
  • authentication-successful
  • dns-response
  • failed-logon
  • failed-vpn-login
  • file-download
  • file-upload
  • nac-logon
  • network-connection-successful
  • process-created
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
AnyConnect
  • process-network
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Duo Access Security
  • account-creation
  • account-deleted
  • account-lockout
  • account-password-reset
  • app-activity
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • failed-vpn-login
  • vpn-login
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Firepower
  • authentication-successful
  • dns-query
  • dns-response
  • failed-vpn-login
  • file-download
  • nac-logon
  • netflow-connection
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • process-created
  • security-alert
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
ISE
  • app-activity
  • authentication-failed
  • authentication-successful
  • computer-logon
  • config-change
  • failed-logon
  • failed-vpn-login
  • nac-failed-logon
  • nac-logon
  • remote-logon
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Meraki MX appliances
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Citrix

ProductEvent TypesMITRE ATT&CK® TTPContent
Citrix Netscaler
  • app-login
  • authentication-failed
  • failed-vpn-login
  • process-created
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
ProductEvent TypesMITRE ATT&CK® TTPContent
Cognitas CrossLink
  • vpn-login
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Datawatch Systems

ProductEvent TypesMITRE ATT&CK® TTPContent
DataWatch
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Dell

ProductEvent TypesMITRE ATT&CK® TTPContent
SonicWALL Aventail
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: F5

ProductEvent TypesMITRE ATT&CK® TTPContent
F5 BIG-IP
  • account-password-change-failed
  • authentication-failed
  • authentication-successful
  • failed-logon
  • failed-vpn-login
  • network-connection-successful
  • remote-logon
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
F5 BIG-IP Access Policy Manager (APM)
  • authentication-failed
  • authentication-successful
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Fortinet

ProductEvent TypesMITRE ATT&CK® TTPContent
Fortinet VPN
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Galaxy

ProductEvent TypesMITRE ATT&CK® TTPContent
Galaxy
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Gallagher

ProductEvent TypesMITRE ATT&CK® TTPContent
Access Control
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Generic Badge Access

ProductEvent TypesMITRE ATT&CK® TTPContent
Generic Badge Access
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Genetec

ProductEvent TypesMITRE ATT&CK® TTPContent
Genetec Badge
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: Honeywell

ProductEvent TypesMITRE ATT&CK® TTPContent
Honeywell Pro-Watch
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models
Honeywell WIN-PAK
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models
honeywell siama
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: Huawei

ProductEvent TypesMITRE ATT&CK® TTPContent
Unified Security Gateway
  • authentication-successful
  • network-alert
  • process-created
  • vpn-login
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: IBM

ProductEvent TypesMITRE ATT&CK® TTPContent
Lotus Mobile Connect
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • vpn-login
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: ICPAM

ProductEvent TypesMITRE ATT&CK® TTPContent
ICPAM
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: Johnson Controls

ProductEvent TypesMITRE ATT&CK® TTPContent
Johnson Controls P2000
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: Juniper Networks

ProductEvent TypesMITRE ATT&CK® TTPContent
Juniper Networks Pulse Secure
  • account-deleted
  • app-activity
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • network-connection-failed
  • vpn-connection
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Juniper SRX
  • authentication-successful
  • failed-vpn-login
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • security-alert
  • vpn-login
  • web-activity-allowed
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Juniper VPN
  • account-deleted
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
  • web-activity-allowed
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: KABA EXOS

ProductEvent TypesMITRE ATT&CK® TTPContent
KABA EXOS
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: Lenel

ProductEvent TypesMITRE ATT&CK® TTPContent
Lenel OnGuard
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models
OnGuard
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Lyrix

ProductEvent TypesMITRE ATT&CK® TTPContent
Lyrix
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Microsoft

ProductEvent TypesMITRE ATT&CK® TTPContent
DirectAccess
  • failed-vpn-login
  • vpn-login
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Routing and Remote Access Service
  • authentication-successful
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Windows
  • account-creation
  • account-deleted
  • account-disabled
  • account-enabled
  • account-lockout
  • account-password-change
  • account-password-change-failed
  • account-password-reset
  • account-switch
  • account-unlocked
  • app-login
  • audit-log-clear
  • audit-policy-change
  • authentication-failed
  • authentication-successful
  • batch-logon
  • computer-logon
  • config-change
  • dcom-activation-failed
  • dns-query
  • dns-response
  • ds-access
  • failed-app-login
  • failed-logon
  • failed-vpn-login
  • file-close
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • local-logon
  • logout-remote
  • member-added
  • member-removed
  • nac-failed-logon
  • nac-logon
  • network-connection-successful
  • ntlm-logon
  • privileged-access
  • privileged-object-access
  • process-created
  • process-network
  • process-network-failed
  • registry-write
  • remote-access
  • remote-logon
  • security-alert
  • service-created
  • service-logon
  • share-access
  • share-access-denied
  • task-created
  • usb-activity
  • usb-insert
  • vpn-login
  • vpn-logout
  • winsession-disconnect
  • workstation-locked
  • workstation-unlocked
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: NCP

ProductEvent TypesMITRE ATT&CK® TTPContent
NCP
  • authentication-failed
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: NetMotion Wireless

ProductEvent TypesMITRE ATT&CK® TTPContent
NetMotion Wireless
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Nortel Contivity

ProductEvent TypesMITRE ATT&CK® TTPContent
Nortel Contivity VPN
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Palo Alto Networks

ProductEvent TypesMITRE ATT&CK® TTPContent
GlobalProtect
  • app-activity
  • authentication-failed
  • authentication-successful
  • config-change
  • failed-logon
  • failed-vpn-login
  • remote-logon
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
NGFW
  • authentication-failed
  • authentication-successful
  • config-change
  • dlp-alert
  • file-alert
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • remote-logon
  • security-alert
  • vpn-login
  • web-activity-allowed
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Paxton

ProductEvent TypesMITRE ATT&CK® TTPContent
NET2DOOR
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: PicturePerfect

ProductEvent TypesMITRE ATT&CK® TTPContent
PicturePerfect
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: Ping Identity

ProductEvent TypesMITRE ATT&CK® TTPContent
PingOne
  • app-login
  • authentication-successful
  • failed-app-login
  • vpn-login
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: RS2

ProductEvent TypesMITRE ATT&CK® TTPContent
RS2
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models
RS2 Technologies
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: RedCloud

ProductEvent TypesMITRE ATT&CK® TTPContent
RedCloud
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: RightCrowd

ProductEvent TypesMITRE ATT&CK® TTPContent
RightCrowd
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: SSL Open VPN

ProductEvent TypesMITRE ATT&CK® TTPContent
SSL Open VPN
  • app-activity
  • app-activity-failed
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: SecureNet

ProductEvent TypesMITRE ATT&CK® TTPContent
SecureNet
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: SecurityExpert

ProductEvent TypesMITRE ATT&CK® TTPContent
SecurityExpert
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: Sensormatik

ProductEvent TypesMITRE ATT&CK® TTPContent
Sensormatik
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Siemens

ProductEvent TypesMITRE ATT&CK® TTPContent
Siemens
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Sonicwall

ProductEvent TypesMITRE ATT&CK® TTPContent
Sonicwall
  • failed-vpn-login
  • network-alert
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Sophos

ProductEvent TypesMITRE ATT&CK® TTPContent
Sophos XG Firewall
  • app-login
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1133 - External Remote Services
  • 1 Rules
  • 1 Models

Vendor: Swipes

ProductEvent TypesMITRE ATT&CK® TTPContent
Swipes
  • physical-access
T1078 - Valid Accounts
  • 7 Rules
  • 3 Models

Vendor: TimeLox

ProductEvent TypesMITRE ATT&CK® TTPContent
TimeLox
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Tyco

ProductEvent TypesMITRE ATT&CK® TTPContent
CCURE Building Management System
  • app-activity
  • app-login
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Vanderbilt

ProductEvent TypesMITRE ATT&CK® TTPContent
Vanderbilt
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Viscount

ProductEvent TypesMITRE ATT&CK® TTPContent
Viscount
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Visma

ProductEvent TypesMITRE ATT&CK® TTPContent
Megaflex
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models

Vendor: Zscaler

ProductEvent TypesMITRE ATT&CK® TTPContent
Zscaler Private Access
  • vpn-login
  • vpn-logout
T1133 - External Remote Services
  • 1 Rules
  • 1 Models